PingOne Attack Paths
ID: 12762ae7-011e-53d3-aff6-bfd7b4c84db2
STIX ID: report--12762ae7-011e-53d3-aff6-bfd7b4c84db2
Feed Name: SpecterOps Blog
This post presents PingOneHound, a free, open-source extension for BloodHound that models PingOne’s identity architecture and RBAC to discover and remediate identity-based attack paths. It explains core PingOne objects (organizations, environments, users, groups, applications, gateways, propagation stores) and demonstrates how role scoping and permissions can lead to abusable outcomes, outlining key abuse primitives such as password resets, group membership changes, role assignments, reading worker app secrets, creating gateway credentials, and extracting propagation store tokens for potential lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
